Privacy policy
Last updated: [PLACEHOLDER: date]. This policy describes how Cleo handles personal data, including data from your Google account. It is written to be read, not to be survived.
Before launch: the fields marked [PLACEHOLDER: …] must be completed with the real details of the operating entity and its suppliers, and the whole document reviewed by a lawyer qualified in German and EU data protection law. The data flows described below are accurate to how Cleo is built; the legal wrapper around them still needs professional sign-off.
1. In short
- Cleo runs as a separate, isolated instance for each customer. Your data is not pooled with anyone else's.
- Your instance and its storage are hosted in Germany.
- We access your Gmail, Google Calendar and Todoist only through the permissions you grant, only to operate your assistant, and for nothing else.
- Your data is never used to train any AI model — ours or a supplier's.
- Cleo drafts emails; it does not send them. Every outgoing message is approved by you.
- You can revoke access at any time from your own Google account, and you can ask us to delete everything.
2. Who is responsible
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
[PLACEHOLDER: full registered company name]
[PLACEHOLDER: street and number]
[PLACEHOLDER: postcode, city, country]
Email: privacy@opencleo.com
Full company details are in the imprint.
Data protection officer: [PLACEHOLDER: name and contact details, or delete if none appointed].
3. What we process, and why
3.1 When you visit this website
Our web server records the usual technical access data: IP address, date and time of the request, the page requested, referrer, browser and operating system version. This is necessary to deliver the page and to defend against attacks.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure website).
- Retention: server logs are deleted after [PLACEHOLDER: e.g. 7 days].
- Cookies: this website sets no cookies and runs no analytics or tracking. There is nothing to consent to, which is why you were not asked.
- Fonts: typefaces are loaded from Google Fonts, which means your IP address is transmitted to Google. [PLACEHOLDER: if this is not acceptable, self-host the two font files and delete this bullet — recommended for a DACH audience]
3.2 When you join the waitlist
We process the email address you give us, and nothing else, in order to contact you about a place on the service.
- Legal basis: Art. 6(1)(a) GDPR (consent), or Art. 6(1)(b) where the contact is a step towards a contract at your request.
- Retention: until you ask us to remove it, or 24 months after the last contact, whichever comes first.
- We do not use waitlist addresses for a newsletter or any other marketing.
3.3 When you are a Cleo customer
This is the substantial part. To act as your assistant, Cleo needs access to the accounts you connect.
| Source | Data | Purpose |
|---|---|---|
| Gmail (via Google OAuth) | Message headers, bodies, attachments metadata, labels, thread structure, your own sent messages | To triage your inbox, summarise what needs you, and prepare draft replies in your writing style. Drafts are created in your own Gmail drafts folder. |
| Google Calendar (via Google OAuth) | Events, times, attendees, locations, descriptions | To brief you on your day, spot conflicts, and propose or arrange times when you ask. |
| Todoist | Tasks, projects, due dates, comments | To record commitments made in email or chat and remind you of them. |
| Telegram | The messages you exchange with your assistant, and your Telegram user ID | This is how you talk to Cleo. Messages are delivered through Telegram's infrastructure. |
| Cleo's own notes | Plain-text notes about your business: people, customers, processes, preferences, a log of what was done | So the assistant improves rather than starting from zero every day. You can read these notes and ask for corrections at any time. |
| Account and billing | Name, business name, address, email, VAT ID, payment records | Contract, invoicing and statutory accounting. |
- Legal basis: Art. 6(1)(b) GDPR — processing is necessary to perform the contract by which we provide you an assistant. Billing records are additionally retained under Art. 6(1)(c) (legal obligation).
- Third parties in your mailbox: your inbox contains other people's personal data. When you connect Gmail, you remain the controller for that correspondence and we process it as your processor under Art. 28 GDPR, on your instructions. A data processing agreement (Auftragsverarbeitungsvertrag) forms part of the contract and is provided at onboarding.
3.4 Google API Services — Limited Use
Cleo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the assistant features you can see — briefings, triage, drafts, calendar handling.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or where required by law.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve or train generalised AI or machine-learning models. Where the assistant uses a third-party language model to produce a draft, the arrangement with that supplier contractually excludes training on the content submitted.
- No human at Cleo reads your Google data except where you specifically ask us to (for example, when you report a problem), where it is necessary for security, or where the law requires it. Any such access is limited and recorded.
Scopes. We request the narrowest permissions that let Cleo do its job, and we tell you what they are before you grant them: [PLACEHOLDER: list the exact OAuth scopes requested, e.g. gmail.modify, calendar.events — must match the Google Cloud console configuration exactly for verification].
4. Where your data is, and who else touches it
Your assistant runs in a container dedicated to you, on servers in Germany. Your files and Cleo's notes about your business live on storage attached to that container. There is no shared customer database and no shared search index.
| Supplier | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of your instance and its storage | Germany (EU) |
| Telegram | Message delivery between you and your assistant | [PLACEHOLDER: state Telegram's processing location and the transfer basis] |
| Language-model suppliers | Generating drafts and summaries from the text passed to them | [PLACEHOLDER: name each supplier actually used, its processing region, and whether an EU region is configured] |
| Todoist (Doist) | Task storage, where you have connected it | [PLACEHOLDER] |
| Payment provider | Invoicing and payment | [PLACEHOLDER: name and location] |
Each of these is engaged under a data processing agreement pursuant to Art. 28 GDPR. Where a supplier processes data outside the EU or EEA, the transfer is based on the European Commission's Standard Contractual Clauses together with supplementary measures, or on an adequacy decision. [PLACEHOLDER: confirm the transfer basis for each non-EU supplier named above]
Being straight about one thing: producing a draft reply requires sending the relevant text to a language-model supplier. That text can include the content of the email being answered. We choose suppliers and contract terms that forbid retention beyond what is needed to return the answer and that forbid training on it. We would rather say this plainly than bury it.
5. How long we keep things
- Email and calendar content: not stored beyond what your assistant needs to work. Cleo reads from Google and writes drafts back to Google; it is not a second archive of your mailbox. [PLACEHOLDER: state the actual working cache retention, e.g. rolling 30 days]
- Cleo's notes about your business: kept for the life of your contract, because that memory is the product. Deleted with your instance.
- Chat history with your assistant: [PLACEHOLDER: state retention period]
- Your instance and all its storage: deleted within 30 days of your contract ending, or within 30 days of a deletion request.
- Invoices and accounting records: retained for the statutory periods under German commercial and tax law (generally 6 or 10 years). These contain billing details, not the content of your mailbox.
- Server logs: see section 3.1.
6. Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — ask what we hold about you. For Cleo's notes this is easy: they are plain text files and we will send them to you.
- Rectification (Art. 16) — have wrong information corrected. You can also just tell your assistant, and it will fix the note.
- Erasure (Art. 17) — have your data deleted.
- Restriction (Art. 18) and objection (Art. 21) — limit or object to processing based on legitimate interest.
- Data portability (Art. 20) — receive your data in a machine-readable form.
- Withdraw consent (Art. 7(3)) at any time, without affecting processing that already happened.
- Complain to a supervisory authority (Art. 77). The competent authority for us is [PLACEHOLDER: name and address of the competent Landesdatenschutzbehörde]. You may also complain to the authority where you live or work.
Write to privacy@opencleo.com. We answer within one month.
Revoking Google access yourself
You do not have to ask us. Go to myaccount.google.com/permissions, find Cleo, and remove access. Your assistant loses the ability to see your mail and calendar immediately. Tell us afterwards and we will delete what remains.
7. Automated decision-making
Cleo sorts and summarises your email and suggests what deserves your attention. This is a recommendation to you, not a decision about you, and it produces no legal or similarly significant effect within the meaning of Art. 22 GDPR. Cleo does not send messages, commit you to anything, or act externally on your behalf without your explicit approval for that specific action.
8. Security
- Each customer runs in an isolated container with its own storage and its own credentials. One customer's assistant has no route to another's data.
- Access tokens for your Google account are stored encrypted and are used only by your instance.
- Traffic is encrypted in transit (TLS); storage is encrypted at rest.
- Administrative access is limited to named people, requires multi-factor authentication, and is logged.
- [PLACEHOLDER: add any certification, penetration test or CASA assessment once completed — Google requires a CASA security assessment for restricted Gmail scopes]
9. Children
Cleo is a service for businesses and is not directed at anyone under 18. We do not knowingly process children's data.
10. Changes to this policy
If we change how we process data, we update this page and change the date at the top. If a change materially affects you as a customer, we tell you directly rather than relying on you noticing.